Back

HIGH

Sensitive Information Disclosure Due to Insecure XML Parsing in langchain-ai/langchain

Published Sep 4, 2025

Description

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd.

Affected products

Remediation

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntr_ai
Published Sep 4, 2025
Updated Sep 4, 2025
Reserved Jul 1, 2025
CISA Vulnrichment
Updated Sep 4, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Sep 4, 2025
ENISA EUVD
Assigner @huntr_ai
Published Sep 4, 2025
Updated Sep 4, 2025
Exploited since n/a
EUVD-2025-26850 GHSA-PC6W-59FV-RH23